Connect with us

Technologies

2022 Black Friday: Make Sure You Avoid All the Elaborate Scams

Scammers don’t take a break during the holidays. Learn what to watch for to protect yourself.

This story is part of Gift Guide, our year-round collection of the best gift ideas.

Black Friday arrives the day after Thanksgiving — which is Nov. 25 this year. It’ll be a day filled with deals on items like headphones and TVs, but with all that potential money flowing from customers to stores, cybercriminals are unfortunately looking to steal some of it.

Scammers work year round, but they turn up their efforts during the high-spending holiday season to exploit the spirit of giving.

The scams range far and wide — as retailers like Amazon, Best Buy and Walmart roll out deals over the holidays, fraudsters create elaborate websites to trick you into spending money on products you’ll never receive. You may receive text messages or emails claiming you’re eligible for a refund for an item you never purchased, just so thieves can get your credit card information. You might even be enticed into donating to a charity that provides homes for abandoned puppies — only to find out it doesn’t actually exist.

Scams come in all shapes and sizes, but there are always red flags to help spot them. Here’s what you need to know about Black Friday scams and how to avoid becoming a victim this holiday season.

For more about security and privacy this holiday season, check out how to protect yourself from identity theft, how to protect your phone app privacy, and the most common cryptocurrency scams.

Fake websites and fraudulent apps go ‘phishing’

In a phishing scheme, the goal is for hackers to get their hands on your personal information, like your credit card number, social security or account password. Pretending to be a large retail corporation, the fraudsters send out an official-looking email or text message, usually with a link to a fraudulent website designed to look just like a legitimate site.

Researchers at security firm Avanan discovered that hackers were sending out spoofed Amazon order notification emails. The email resembled your run-of-the-mill order confirmation, except that the order is false and the charge is significant.

Naturally, if you believe you’re being charged for a substantial amount, you would want to reach out to Amazon. But in this instance, if you use the link in the phishing email to get in contact, you’ll be redirected to a fake Amazon webpage with a false phone number to dial. If you call, the fraudsters won’t initially pick up, but they’ll soon call back, asking you to provide your card number, expiration date and CVV to “cancel the order.” And just like that, they’ve got your information.

These types of attacks are commonplace throughout the year, but expect a surge in messages claiming to be from Amazon, Best Buy, Walmart, Target or other large retailers during the holidays.

If you receive an email asking you to update your payment method or requesting other personal information, contact the company’s help desk to make sure the email is legit before you do anything else.

Other ways to identify a phishing email, according to the Federal Trade Commission and StaySafeOnline.org, include:

  • The sender’s email address looks almost right but contains extra characters or misspellings.
  • There are misspellings or bad grammar either in the subject line or anywhere in the body.
  • They address you with generic terms (“Mr.” or “Ms.” or “Dear Customer”) instead of by name.
  • The message warns that you need to take immediate action and asks you to click a link and enter personal details, especially payment information.
  • The messages promise a refund, coupons or other freebies.
  • The company logo in the email looks low-quality or just plain wrong.

Credit card skimming goes all-digital

You’ve seen it in movies. A hacker places an object over a card reader, disguised to look like part of the ATM, and then waits for people to swipe their cards. A day or week later, the thief takes the object — known as a skimmer — back and collects the mountain of stolen card information stored inside, which they can then use to make purchases, withdraw money and more.

Instead of using physical hardware to steal payment card numbers, hackers can insert malicious code directly on a website to do the same thing as traditional skimming, but with online payment information instead.

Regarding e-skimming incidents — sometimes called Magecart attacks after the name of the software used — Tim Mackey, principal security strategist for Synopsis, a digital security company, warns, “There isn’t an obvious way for the average person to be able to identify if or when a website has been compromised. The only potential tell-tale sign might be that the website itself doesn’t quite look ‘right.'”

Mackey suggests a few strategies you can can use to protect yourself:

  • Don’t save your credit card information on retail sites.
  • If possible use a third-party payment method like Apple Pay, Google Wallet or PayPal.
  • Enable purchase alerts on all your credit cards.
  • Disable international purchases on all credit cards.
  • Only make purchases over your home network or cellular network, never on a public Wi-Fi where your payment could be intercepted.

Avoid the ‘Secret Sister’ gift exchange — it’s a pyramid scheme

Originating on Facebook, this sketchy gift exchange among internet strangers plays off the popular workplace practice of “Secret Santa,” a game where each person in a group buys a present for one other randomly selected group member, without the gift-giver revealing their identity.

Instead, in Secret Sister, it’s a pyramid scheme dressed up in holiday clothes, according to the Better Business Bureau. The “Secret Sister” exchange invitation promises you’ll receive about $360 worth of gifts after purchasing and mailing a $10 gift for someone else. A variation includes swapping bottles of wine. And there’s even “Secret Santa Dog,” in which you gift money to a “secret dog.”

Unfortunately, bad math hasn’t stopped this scam from resurfacing year after year. If you fall for it, you’ll probably be out 10 bucks when you don’t receive any gifts in return. You might lose personal details too, because the scam involves sending your name, email address and phone number to people you’ve never met in person.

The Better Business Bureau recommends you deal with any request to become a Secret Sister by ignoring it — do not give your personal details to online strangers. You can also report the invitation to Facebook or whichever social network you were approached on.

Your donations might be going to a ‘faux charity’

During the holiday season, it’s not uncommon to give back to the community. In fact, nonprofit organizations typically see an increase during the fall. The last three months of the year make up 36% of all charitable giving during the year, according to Blackbaud Institute, which creates fundraising applications.

Unfortunately, scammers take advantage of this generosity to make a bundle for themselves.

The way these charity fraud scams typically work are by impersonating other successful charities. And it’s no wonder they work: The scammers come up with real-sounding charity names, create credible websites, run successful social media campaigns — and they’re persistent.

Scammers typically call you using local phone numbers, which give you a false sense of security. However, it’s incredibly easy to spoof an area code. Next they’ll make their pitch, and it’ll be a good one. It will tug at your heart-strings, but they’ll never actually specify how they’ll help. And they may even claim that you’ve made a donation before, and suggest that you make another, and that if you do, it’ll be tax-deductible. And it’ll all be a lie.

If you get a call from a charity and sense some red flags, the AARP and FTC suggest that you do the following:

  • Do your research. Use a watchdog like CharityWatch to get more information about a charity and learn how credible it is. Or use Google.
  • Pay close attention to the charity name and website. False charities like to mimic other popular charities. If it seems too close in name to another, it might not be real.
  • Keep track of your donations. Even if you accidentally donate to a scammer, you need to ensure that the donation isn’t recurring.
  • Don’t give away all your personal information. Of course it’s normal to provide your card information, but don’t do the same with your Social Security number or bank account number.
  • Don’t make a cash donation. Unless you’re certain about a charity’s credibility, don’t give away cash, gift cards, or cryptocurrency.

For any charitable donations that you make, you can also use the IRS tax-exempt organization search tool to make sure that the charity you’re contributing to is legitimate and that your gift can be deducted on your income tax return.

Find The Perfect Gift

AllUnder $10Under $20Under $50Under $100Under $250
allmomsdadsgrandparentsfitnesstravelersteenspreteenstechgamingfoodieshomeromanticjewelrykids
107 results

Technologies

Passengers and crew foil co-pilot’s apparent attempt to crash FlyDubai flight to Israel

One of the pilots on a FlyDubai flight headed for Israel stabbed the second pilot, according to Israeli Prime Minister Benjamin Netanyahu.

On-duty flight crew and passengers managed to foil a pilot’s apparent attempt to crash a FlyDubai flight, after reports emerged of a fight in the cockpit.

The incident on flight FZ1073 from Dubai to Tel Aviv happened when a co-pilot stabbed a pilot, according to Israeli Prime Minister Benjamin Netanyahu, who praised the victim’s quick thinking.

“Despite being stabbed and seriously injured, he fought back, resisted, opened the cockpit door, and enabled passengers and crew to overpower the attacker — preventing a catastrophic mid-air disaster. He saved the lives of 174 people, including Israeli citizens and other nationals,” Netanyahu wrote in a post on X.

FZ1073 was diverted to the Tabuk airport in Saudi Arabia, the airline said, after being successfully secured and diverted by flight crew.

FlyDubai in a statement said that an “altercation” occurred on the flight deck of the plane, but did not mention a stabbing.

However, the airline added that the underlying reasons and motives for the clash is currently unknown, urging all parties to refrain from speculation.

The injured pilot was identified by Netanyahu as Indian national Smit Machchhar. No details have been released on the identity of the attacker, except that he was being interrogated by Saudi authorities.

The Indian embassy in Riyadh said on X that Machchhar is in a hospital in Tabuk, and is reported to be in stable condition.

The Israeli Prime Minister also identified the passenger who broke into the cockpit as Yaniv Hayun, calling him a “hero” and adding he deserved “a global medal of honor.”

Flight data from tracking site FlightRadar24 showed that the plane had experienced extreme altitude fluctuations before broadcasting a “general emergency” squawk code.

FZ1073 had dropped from over 14,000 feet in just 29 seconds, and FlightRadar24 also added that vertical speeds ranging from approximately -30,000 to +10,000 feet per minute were observed from the transponder data.

For context, vertical speeds during normal operations rarely exceed plus or minus 4,000 feet per minute, it added.

Continue Reading

Technologies

South Korean President Lee resists Alaska LNG project after Trump highlights Seoul’s involvement

South Korean President Lee Jae‑myung has conditioned his country’s participation in the Alaska LNG project on financial viability and legal compliance, pushing back against President Trump’s push for the $50‑billion venture while other $200‑billion U.S. investments move forward.

South Korea’s $200 billion investment in the United States, which President Donald Trump said would transform America “for generations,” is not yet finalized in full.

The South Korean investment blueprint includes nuclear power plants, a natural‑gas power facility in Texas, and potentially the long‑planned Alaska liquefied natural gas project.

Trump posted on Truth Social late Wednesday that the two nations had agreed to move forward on the Alaska LNG venture, estimating its value at $50 billion. This prompted a response from South Korean President Lee Jae‑myung, who stressed that participation in some projects remains tied to commercial considerations.

In an X post Thursday local time, Lee said that involvement in the Alaska LNG project hinges on its financial viability and legal compliance. He added that investments in nuclear power plants would also require a plant‑by‑plant assessment of commercial feasibility.

The US‑South Korea joint statement Wednesday also noted that work on the project is contingent on “commercial reasonableness,” without detailing allocations toward the venture.

The Alaska LNG project aims to move natural gas roughly 1,300 km (800 miles) from fields on Alaska’s North Slope to the state’s southern region, where it would be liquefied for export to markets including Asia, according to Yonhap. The initiative has long faced scrutiny over its economics, given the substantial upfront capital required.

Industry Minister Kim Jung‑kwan labeled it “high‑risk” last year and said participation would be challenging unless the project could generate sufficient cash flow.

Overall, the investment package allocates $22.3 billion for a 6,472‑megawatt natural‑gas power plant in Encinal, Texas, which will supply electricity to nearby data centers. The venture will be led by developer Related Cos. and U.S. power provider NextEra Energy.

Trump said the investments would turn South Korea’s commitments into “huge construction projects” and create “tens of thousands of American jobs.”

“These are massive energy projects, adding power capacity in the United States,” Trump remarked. “This is new construction, new manufacturing, and great jobs for American workers.”

The two countries said they would seek to broaden Korean firms’ involvement in the Texas project across equipment supply, engineering, construction, and long‑term operations and maintenance. The U.S. also plans to give Korean companies opportunities to supply equipment, including turbines, for similar projects domestically.

Another $120 billion has been earmarked for plans to build eight large‑scale nuclear reactors in the United States. Of that sum, $100 billion is designated for construction costs and $20 billion for contingency reserves.

The nuclear accord was signed by both governments as well as Westinghouse Electric, Korea Electric Power Corp., and Korea Hydro & Nuclear Power. The plan also calls for Korean firms to pursue a potential significant minority stake in Westinghouse, with terms subject to commercial negotiations.

Continue Reading

Technologies

Washington’s big crypto bill is stuck. The SEC is pushing ahead anyway

The SEC has proposed new rules that would make it easier for investment advisers and regulated funds to hold cryptocurrencies on behalf of clients.

The U.S. Securities and Exchange Commission has proposed new rules that would make it easier for investment advisers and regulated funds to hold cryptocurrencies on behalf of clients, as U.S. regulators push ahead with writing crypto rules after a sweeping legislation stalled in Congress.

The proposal, announced Thursday stateside, would establish a tailored framework governing how registered investment advisers, investment companies and business development companies hold custody of crypto assets.

The changes are aimed at modernizing decades-old custody requirements and removing regulatory barriers that the SEC says have limited advisers’ ability to offer crypto-related investments.

Under the proposed rules, crypto assets could be held in self-custody under “certain circumstances,” while state trust companies could also serve as custodians for crypto assets belonging to clients and regulated funds.

The changes could also give regulated funds greater scope to offer investors crypto-related investment strategies, according to the SEC.

SEC Chairman Paul Atkins said existing regulations had failed to keep pace with the rapid expansion of digital assets, which have grown into a multi-trillion-dollar market.

“Today’s proposal would provide a clear regulatory framework for the custody of crypto assets, giving investment advisers and funds a compliant pathway where none existed before,” Atkins said.

The proposal comes as U.S. regulators push ahead with building out a crypto rulebook under their existing authority after the Clarity Act, a sweeping crypto market structure bill, stalled in the Senate in September.

That marks another step in the SEC’s broader effort to rewrite the U.S. regulatory framework for digital assets under Atkins, and will be open for public comment for 60 days after it is published in the Federal Register.

With broader crypto legislation stalling in Congress, regulators are exerting their existing powers to address individual parts of the market, said Jeff Ko, chief analyst at blockchain infrastructure service provider ViaBTC.

“What we’re increasingly seeing is the SEC using the authority it already has to solve individual bottlenecks one by one, issuance, tokenization, trading exemptions and now custody,” he told CNBC via email.

The regulatory push also comes as crypto markets show signs of renewed momentum following a volatile start to the year. Bitcoin has rebounded over 40% from its July low, as improving risk appetite have helped revive demand for digital assets.

The recovery follows a prolonged downturn from late 2025 into the first half of 2026.

Continue Reading

Trending

Copyright © Verum World Media